VulnerabilityModified
CVE-2024-4629
A vulnerability was found in Keycloak.
MEDIUM 6.5EPSS 0.79%
Does this matter?
Lower severity and a low EPSS score (0.79%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses at passwords than intended, potentially compromising account security on affected systems.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.79% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-837
- Affected
- redhat/keycloak · redhat/build of keycloak · redhat/single sign-on · redhat/openshift container platform · redhat/openshift container platform for linuxone · redhat/openshift container platform for power · redhat/openshift container platform ibm z systems
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2024:6493Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6494Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6495Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6497Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6499Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6500Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6501Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2024-4629Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2276761Issue Tracking, Vendor Advisory
- https://github.com/hnsecurity/vulns/blob/main/HNS-2024-09-Keycloak.md
- https://security.humanativaspa.it/an-analysis-of-the-keycloak-authentication-system/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.